PkgRadar

npm · registry.npmjs.org

@waline/vercel

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 1.40.3

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/src/service/notify.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.40.3Review52026-05-29
1.40.2Review52026-05-29
1.40.1Review52026-05-28
1.39.3Low risk02026-05-27
1.40.0Low risk02026-05-27

Block this in CI

PkgRadar gates @waline/vercel (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @waline/[email protected]